Lucene search

K
redhatcveRedhat.comRH:CVE-2019-0192
HistoryOct 10, 2019 - 5:40 p.m.

CVE-2019-0192

2019-10-1017:40:21
redhat.com
access.redhat.com
45

EPSS

0.948

Percentile

99.3%

A flaw was found in the Apache Solr’s Config API, where it would permit the configuration of the JMX server via an HTTP POST request. An attacker could use this flaw to direct traffic to a malicious RMI server, and then trigger remote code execution or conduct further attacks.

Mitigation

  • Upgrade to 6.6.6 or later
  • Disable the ConifgAPI if not in use (disable.configEdit=true)
  • Use other external means to ensure only trusted traffic is allowed (block POST requests to the config API from external sources)